[pkg-vuln] CVE-2026-25645 in requests@2.32.5 #330

Closed
opened 2026-04-02 17:37:21 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: requests @ 2.32.5
Fixed in: 2.33.0

Requests is a HTTP library. Prior to version 2.33.0, the requests.utils.extract_zipped_paths() utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-25645

**Severity:** MEDIUM **Package:** `requests` @ `2.32.5` **Fixed in:** `2.33.0` Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-25645
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-04-02 17:37:21 +00:00
kert added the qualityci labels 2026-04-02 17:37:21 +00:00
kert closed this issue 2026-04-10 00:57:10 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#330